Attorney's Docket No.: 18897-002001 / 1150-110US 
Amendment to the Claims : 

This listing of claims replaces all prior versions, and 
listings, of claims in the application: 

1. (Currently amended) A method for identifying network 
conditions affecting a computer network, the network having a 
mechanism for sending packet bursts along a path in the network 
and receiving said packet bursts at an end of the path, the 
method comprising: 

providing a plurality of example signatures indicative of a 
plurality of specific network conditions , each of the example 
signatures including information indicative of a specific and 
different network condition, and at least a part of one or more 
example signatures indicative of one or more of packet loss, 
packet ordering and packet timings, wherein each specific 
network condition causes a unique behavior directly indicative 
of data transmission performance in the computer network; 

acquiring test data, which test data is based on actual 
propagation of test packets along the path; 

creating a test signature from the test data, said test 
signature being an organized collection of information obtained 
from said test data, and at least a part of said test signature 
indicative of one or more of packet loss, packet ordering and 
packet timings; 
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comparing the test signature to the example signatures; 

and, 

identifying at least one of the example signatures which 
matches the test signature according to a match criterion, 
wherein said identifying determines thereby — identifying at least 
one of said plurality of specific network condition s which is 
affecting the computer network. 

2. (Original) The method of claim 1 wherein comparing 
the test signature to the example signatures comprises computing 
a similarity measure between the test signature and each of the 
example signatures. 

3. (Original) The method of claim 1 wherein 

the test signature comprises a plurality of values, 
each of the example signatures comprise a set of 

corresponding values and, 

computing the similarity measure between the test signature 

and an example signature comprises computing a fit between each 

of the values of the test signature and the corresponding value 

of the example signature. 
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4. (Original) The method of claim 3 wherein computing a 
fit between a value of the test signature and a corresponding 
value of the example signature is performed by evaluating a 
function associated with the value. 

5. (Original) The method of claim 3 wherein computing 
the fit between each of the values of the test signature and the 
corresponding value of the example signature comprises 
performing a computation substantially mathematically equivalent 
to : 

G(x,m)=A exp (-B (x-m) 2 ) 

where x is a value in the test signature, m is the 
corresponding value of the example signature and A and B are 
coefficients . 

6. (Original) The method of claim 3 wherein computing 
the fit between each of the values of the test signature and the 
corresponding value of the example signature comprises 
performing a computation substantially mathematically equivalent 
to: 
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where x is a value in the test signature, m is the 
corresponding value of the example signature, and C and A, are 
coefficients . 

7. (Previously presented) The method of claim 6 wherein 
values for C and X are associated with each corresponding value 
of the example signature and performing the computation 
comprises using the values for C and X associated with the 
corresponding value of the example signature with which the fit 
to a value of the test signature is being computed. 

8. (Original) The method of claim 2 wherein computing a 
similarity measure comprises performing a chi-squared 
calculation . 

9. (Original) The method of claim 2 comprising 
normalizing the similarity measures corresponding to the example 
signatures before identifying at least one of the example 
signatures which matches the test signature. 

10. (Original) The method of claim 9 wherein normalizing 
the similarity measures is based at least in part upon the 
similarity measure that would be obtained in a lossless network. 
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11. (Original) The method of claim 10 wherein normalizing 
the similarity measures is based at least in part upon the 
similarity measure that would be obtained if the test signature 
and example signature were identical. 



12. (Original) The method of claim 11 wherein normalizing 
the similarity measures comprises evaluating for each similarity 
measure : 




where FIT is the similarity measure, Formalized is the 
normalized similarity measure, F no i oss is the similarity measure 
that would be obtained if the test data reported no loss of 
packets and F matC h is the similarity measure that would be 
obtained if the test signature and example signature were 
identical . 



13. (Original) The method of claim 9 comprising adjusting 
one or more of the similarity measures based upon an individual 
set of rules associated with that similarity measure before 
identifying at least one of the example signatures which matches 
the test signature. 



14. (Original) The method of claim 13 wherein the 
individual set of rules includes one or more rules based upon 
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factors including one or more of: a number of ICMP network 
unreachable messages; a number of ICMP host unreachable 
messages; a number of ICMP destination unreachable messages; a 
number of ICMP port unreachable messages; a number of ICMP 
protocol unreachable messages; a number of ICMP fragmentation 
required messages; a number of ICMP TTL expired messages; a 
number of ICMP source quench messages; a number of ICMP redirect 
messages; a number of ICMP router advertisement messages; a 
number of ICMP parameter problem messages; a number of ICMP 
security problem messages; a number of unsolicited packets; a 
number of out-of-sequence packets; a non-standard MTU detected; 
and a number of timed out packets. 



15. (Original) The method of claim 1 wherein the test 
signature comprises, packet loss statistics for a plurality of 
positions within bursts of test packets of a first size. 



16. (Original) The method of claim 15 wherein the test 
signature comprises, packet loss statistics for a plurality of 
positions within bursts of test packets of a second size. 



17. (Original) The method of claim 16 wherein one of the 
first and second sizes is not more than three times a minimum 
packet size for the path. 
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18. (Previously presented) The method of claim 17 wherein 
the other one of the first and second sizes is within 10% of a 
maximum packet size for the path. 

19. (Original) The method of claim 16 wherein one of the 
first and second sizes is within 10% of a maximum packet size 
for the path. 

20. (Original) The method of claim 16 wherein the test 
signature comprises, packet loss statistics for a plurality of 
positions within bursts of test packets of a third size wherein 
the third size is intermediate the first and second sizes. 

21. (Original) The method of claim 1 wherein the test 
signature comprises a mean packet loss for bursts of packets of 
each of a plurality of sizes. 

22. (Original) The method of claim 21 comprising 
determining the mean packet loss, BrAvg substantially as 
follows : 
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where n is a number of packets in each burst, 1 ± is the loss 
ratio for the i th packet in the burst and i is an index which 
ranges over all of the packets in the burst. 

23. (Original) The method of claim 1 wherein the test 
signature comprises a first moment of packet losses within 
bursts of packets of a given size. 

24. (Original) The method of claim 1 wherein the test 
signature comprises a first moment of packet losses within 
bursts of packets for bursts of packets of each of a plurality 
of sizes. 

25. (Original) The method of claim 24 comprising 
determining the first moment of packet losses, BrMom, 
substantially as follows: 

where 1± is the loss ratio for the i th packet in the burst 
and i is an index which ranges over all of the packets in the 
burst . 
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26. (Original) The method of claim 1 wherein the test 
data includes data regarding the propagation of datagrams along 
the test path. 

27. (Original) The method of claim 26 wherein the test 
signature comprises one or more packet loss statistics for the 
datagrams . 

28. (Original) The method of claim 27 wherein the test 
data comprises information regarding the propagation of 
datagrams of a plurality of sizes along the test path and the 
test signature comprises packet loss statistics for datagrams of 
each of the plurality of sizes. 

29. (Original) The method of claim 1 wherein the path is 
a closed path. 

30. (Original) The method of claim 29 wherein the packets 
comprise ICMP ECHO packets. 

31. (Original) The method of claim 6 wherein the test 
signature comprises a mean packet loss for bursts of packets of 
each of a plurality of sizes. 
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32. (Original) The method of claim 31 comprising 
determining the mean packet loss, BrAvg substantially as 
follows : 



where n is a number of packets in each burst, 1 ± is the loss 
ratio for the i th packet in the burst and i is an index which 
ranges over all of the packets in the burst. 



33. (Original) The method of claim 16 wherein the test 
signature comprises a first moment of packet losses within 
bursts of packets of the first size. 



34. (Original) 
signature comprises a 
bursts of packets for 
second sizes. 



The method of claim 16 
first moment of packet 
bursts of packets of e< 



wherein the test 
losses within 
ich of the first and 



35. (Original) The method of claim 34 comprising 
determining the first moment of packet losses, BrMom, 
substantially as follows: 
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where 1 ± is the loss ratio for the i th packet in the burst 
and i is an index which ranges over all of the packets in the 
burst . 

36. (Original) The method of claim 16 wherein the 
plurality of example signatures comprise example signatures 
corresponding to two or more of: a small queues condition; a 
lossy condition; a half-full duplex conflict condition; a full- 
half duplex conflict condition; an inconsistent MTU condition; a 
long half-duplex link condition; and a media errors condition. 

37. (Currently amended) Apparatus for identifying 
network conditions affecting a computer network, the network 
having a mechanism for sending packets in bursts along a path in 
the network and receiving the packet bursts at an end of the 
path, the apparatus comprising: 

a data store holding a plurality of example signatures 
indicative of a plurality of specific network conditions , each 
of the example signatures including information indicative of a 
specific and different network condition, and at least a part of 
one or more example signatures indicative of one or more of 
packet loss, packet ordering and packet timings, wherein each 
specific network condition causes a unique behavior directly 
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indicative of data transmission performance in the computer 
network; 

an input for receiving test data, which test data is based 
on actual propagation of test packets along the path; 

means for creating a test signature from the test data, 
said test signature being an organized collection of information 
obtained from said test data, and at least a part of said test 
signature indicative of one or more of packet loss, packet 
ordering and packet timings; 

means for comparing the test signature to the example 
signatures; and, 

means for identifying at least one of the example 
signatures which matches the test signature, wherein said 
identifying determines thereby identifying at least one of said 
plurality of specific network condition s which is affecting the 
computer network. 

38. (Original) The apparatus of claim 37 wherein the 
means for identifying at least one of the example signatures 
which matches the test signature comprises an expert system and 
a rule base. 
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39. (Original) The apparatus of claim 38 wherein the rule 
base includes rules which accept as input additional information 
other than the test signature. 

40. (Original) The apparatus of claim 39 wherein the 
additional information comprises one or more of: a number of 
ICMP network unreachable messages; a number of ICMP host 
unreachable messages; a number of ICMP destination unreachable 
messages; a number of ICMP port unreachable messages; a number 
of ICMP protocol unreachable messages; a number of ICMP 
fragmentation required messages; a number of ICMP TTL expired 
messages; a number of ICMP source quench messages; a number of 
ICMP redirect messages; a number of ICMP router advertisement 
messages; a number of ICMP parameter problem messages; a number 
of ICMP security problem messages; a number of unsolicited 
packets; a number of out-of-sequence packets; a non-standard MTU 
detected; 

and a number of timed out packets. 

41. (Original) The apparatus of claim 37 wherein the 
example signatures comprise example signatures corresponding to 
two or more of: a small queues condition; a lossy condition; a 
half-full duplex conflict condition; a full-half duplex conflict 
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condition; an inconsistent MTU condition; a long half-duplex 
link condition; and a media errors condition. 

42. (Original) The apparatus of claim 40 wherein the 
means for comparing the test signature to the example signatures 
comprises means for calculating a similarity measure between the 
test signature and each of the example signatures. 

43. (Previously presented) The apparatus of claim 42 
wherein the test signature comprises a plurality of values, each 
of the example signatures comprise a set of corresponding values 
and, the means for calculating a similarity measure between the 
test signature and each of the example signatures comprises 
means for computing a fit between each of the values of the test 
signature and the corresponding value of the example signature. 

44. (Original) The apparatus of claim 42 wherein the 
means for comparing the test signature to the example signatures 
comprises a neural network. 

45. (Currently amended) Apparatus for identifying network 
conditions affecting a computer network, the network having a 
mechanism for sending packets in bursts along a path in the 
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network and receiving the packet bursts at an end of the path, 
the apparatus comprising: 

a data store holding a plurality of example signatures 
indicative of a plurality of specific network conditions , each 
of the example signatures including information indicative of a 
specific and different network condition, and at least a part of 
one or more example signatures indicative of one or more of 
packet loss, packet ordering and packet timings, wherein each 
specific network condition causes a unique behavior directly 
indicative of data transmission performance in the computer 
network; 

an input for receiving test data, which test data is based 
on actual propagation of test packets along the path; 

a test signature creation mechanism configured to create a 
test signature based upon the test data, said test signature 
being an organized collection of information obtained from said 
test data, and at least a part of said test signature indicative 
of one or more of packet loss, packet ordering and packet 
timings ; 

a comparison system configured to derive a similarity 
measure between the test signature and each of the plurality of 
example signatures; and, 

a selection system configured to identify at least one of 
the example signatures which best matches the test signature, 



16 



Attorney's Docket No.: 18897-002001 / 1150-110US 

wherein said selection system identifies thereby identifying at 
least one of said plurality of specific network condition s which 
is affecting the computer network. 

46. (Original) The apparatus of claim 45 comprising a 
data processor wherein the test signature creation mechanism, 
comparison system, and selection system each comprise a set of 
software instructions in a program store accessible to the 
processor . 

47. (Original) The apparatus of claim 45 wherein the 
example signatures comprise, packet loss statistics for a 
plurality of positions within bursts of test packets of a first 
size . 

48. (Original) The apparatus of claim 47 wherein the 
example signatures comprise packet loss statistics for a 
plurality of positions within bursts of test packets of a second 
size . 

49. (Original) The apparatus of claim 48 wherein the 
example signatures comprise packet loss statistics for a 
plurality of positions within bursts of test packets of a third 
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size wherein the third size is intermediate the first and second 
sizes . 

50. (Original) The apparatus of claim 49 wherein the 
example signatures comprise a mean packet loss for bursts of 
packets of each of a plurality of sizes. 

51. (Original) The apparatus of claim 49 wherein the 
example signatures comprise a first moment of packet losses 
within bursts of packets of a size. 

52. (Original) The apparatus of claim 49 wherein the 
example signatures comprise a first moment of packet losses 
within bursts of packets for bursts of packets of each of a 
plurality of sizes. 

53. (Original) The apparatus of claim 49 comprising a 
test packet sequencer connected to dispatch a sequence of test 
packets along a network path. 

54. (Original) The apparatus of claim 53 wherein the test 
packet sequencer is configured to generate and to dispatch onto 
the path multiple bursts of ICMP ECHO packets. 
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55. (Original) The apparatus of claim 45 comprising a set 
weighting coefficients, fitting coefficients, or both weighing 
and fitting coefficients associated with one or more of the 
example signatures. 

56. (Currently amended) A program product comprising a 
computer readable medium carrying a set of computer-readable 
signals comprising instructions which, when executed by a 
computer processor, cause the data processor to execute a method 
for identifying network conditions affecting a computer network, 
the network having a mechanism for sending packet bursts along a 
path in the network and receiving said packet bursts at an end 
of the path, the method comprising: 

providing a plurality of example signatures indicative of a 
plurality of specific network conditions , each of the example 
signatures including information indicative of a specific and 
different network condition, and at least a part of one or more 
example signatures indicative of one or more of packet loss, 
packet ordering and packet timings, wherein each specific 
network condition causes a unique behavior directly indicative 
of data transmission performance in the computer network; 

acquiring test data, which test data is based on actual 
propagation of test packets along the path; 
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creating a test signature from the test data, said test 
signature being an organized collection of information obtained 
from said test data, and at least a part of said test signature 
indicative of one or more of packet loss, packet ordering and 
packet timings; 

comparing the test signature to the example signatures; 

and, 

identifying at least one of the example signatures which 
matches the test signature according to a match criterion, 
wherein said identifying determines thereby identifying at least 
one of said plurality of specific network condition s which is 
affecting the computer network. 

57. (Previously presented) The method of claim 15 wherein 
the test signature further comprises additional measures. 

58. (Previously presented) The method of claim 57 wherein 
the additional measures include one or more of: measures derived 
from packet or burst loss statistics; measures derived from 
other statistics relating to propagation of test packets along 
the path; relative measures; and test conditions. 

59. (Previously presented) The method of claim 57 wherein 
the additional measures are based on ICMP messages from network 
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devices along the path, the ICMP messages containing information 
relating to one or more of: network errors; network congestion; 
and packet timeouts. 



60. (Previously presented) The method of claim 57 wherein 
the additional measures are based on information regarding 
network topology including one or more of: maximum transfer 
unit, RMON message; and SNMP message. 



61. (Previously presented) The method of claim 1 wherein 
the test data comprises information regarding one or more of: 
connectivity, maximum transmission unit, network device 
responsivity; and time for test packets to traverse the path. 



62. (Previously presented) The method of claim 1 wherein 
the test data comprises information regarding one or more of: 
lost packets; final inter-packet separation; hop number, hop 
address, measured MTU, reported MTU, error flag and information 
relating to the packet bursts prior to sending along the path. 



63. (Previously presented) The method of claim 62 wherein 
the test data comprises information regarding derivatives of 
said information. 
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64. (Previously presented) The method of claim 1 wherein 
the test signature comprises one or more functions, the one or 
more functions relating to one or more of: packet loss 
statistics; round trip time; and final inter-packet spacing. 

65. (Previously presented) The method of claim 64 wherein 
the test signature comprises one or more higher-order functions 
derived from said one or more functions. 

66. (Previously presented) The method of claim 29 wherein 
one or more of the test packets are formatted using TCP protocol 
or UDP protocol. 

67. (Previously presented) The method of claim 66 wherein 
the one or more test packets formatted using TCP or UDP protocol 
are returned from an end host by software or hardware. 

68. (Previously presented) The method of claim 66 wherein 
the test signature comprises packet loss statistics derived from 
the one or more of the test packets formatted using TCP protocol 
or UDP protocol. 
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69. (Previously presented) The method of claim 1 wherein 
the path is an open path wherein test packets are sent from one 
location and received at a different location. 

70. (Previously presented) The method of claim 69 wherein 
the test signature comprises packet loss statistics. 
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